Florida DMV Breach: 200K Records at Risk
ShinyHunters claims a Florida DMV breach, threatening to release 200,000 records by September 11.
The extortion group ShinyHunters has claimed responsibility for breaching a Florida government database, putting the personal information of hundreds of thousands of drivers at risk. The group says it accessed the Florida Department of Highway Safety and Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and stole more than 200,000 records, according to a report from CSO Online.
As proof, the attackers published a screenshot of a record belonging to Jeffrey Epstein, showing sensitive details like an address, Social Security number, date of birth, driver’s license number, and registered vehicles. The claimed breach follows closely on the heels of an investigation into a separate underground service offering over 153 million digital scans of US and Canadian driver’s licenses, a development that has already drawn FBI attention.
Deadline Set for Data Release
ShinyHunters has given the Florida DMV until September 11 to negotiate before the stolen information is released, according to the group’s leak-site posting. The group claims it gained access through a password-reset weakness and then compromised multiple accounts, including those it says belonged to DMV employees. It allegedly queried driver records by ID and downloaded pages and images.
DAVID is a restricted system that provides authorized users—such as law enforcement—with access to extensive driver and vehicle information. A successful intrusion into this system could yield far more than just names and license numbers, potentially exposing a wealth of personal data.
What a Full Record Reveals
“A complete scan gives criminals much more than an identification number – it can reveal a person’s photograph, signature, address, date of birth and other information contained in a legitimate government credential,” said Danny Jenkins, CEO of ThreatLocker, in the CSO Online report. “Criminals could potentially use this data to open fraudulent accounts, conduct targeted phishing and password-reset attacks, commit insurance, medical, tax or government-benefit fraud, or create convincing synthetic identities.”
Jenkins’ warning underscores the value of the data at stake. Unlike a credit card number, a driver’s license contains immutable personal details that can be exploited for years.
“The greatest concern is the permanence of this information,” he said. “Consumers can replace a credit card or password, but they cannot easily replace their face, birth date, signature, or identity history.”
— Danny Jenkins, CEO of ThreatLocker, speaking about the potential identity theft risks.
Two Separate Data Sources
The Florida incident and the Nexus case involve different sources of driver’s license data. ShinyHunters claims to have accessed a restricted Florida government database used by law enforcement and other authorized users to look up driver and vehicle records.
The Nexus database, by comparison, contained scans of government-issued IDs collected by IDScan’s identity-verification technology. The breach exposed millions of scanned IDs and led to an FBI investigation and multiple lawsuits. IDScan.net has formally confirmed its breach, while the Florida DMV has not publicly confirmed the ShinyHunters claim yet.
A Familiar Pattern for ShinyHunters
The incident fits ShinyHunters’ usual pay-or-leak playbook. In the past, the group has compromised organizations, demonstrated access with samples, and then used a publication deadline to pressure victims. One such operation involved the 2024 Snowflake customer-data campaign, which hit organizations including Ticketmaster, AT&T, and Santander Bank.
This history suggests the September 11 deadline is a tactic to force a quick payout, but it also means the threat to release the data is credible.
Uncertainty and Risk
With no public confirmation yet beyond ShinyHunters’ dark web claim and its account of how it allegedly carried out the breach, it remains to be seen how the group’s September 11 deadline will play out.
However, if the claims prove to be true, the exposed information could pose significant identity-theft risks. Jenkins spelled out the most troubling part: much of the information contained on a driver’s license cannot simply be replaced.
Steps to Mitigate Identity Theft
Jenkins recommended freezing credit, monitoring accounts, and using stronger authentication to reduce risks from the breach. These steps can help individuals protect themselves if their data is exposed.
For now, the focus is on verifying the breach and preparing for the potential fallout.
Why This Matters
This incident, if confirmed, could have lasting consequences for Florida residents. The permanence of the data means that even if the deadline passes without a public release, the stolen information could still be sold or used in future attacks. This could mean a prolonged period of heightened risk for identity theft and fraud for those affected.
The outcome of the September 11 deadline will be telling, but regardless, the breach highlights the vulnerabilities in government databases and the need for robust security measures.
Sources
- CSO Online Original source
Continue Reading
Slim Spider Targets Crypto Custody in Brazil
CrowdStrike uncovers Brazil-based threat actor Slim Spider stealing cloud credentials to access cryptocurrency custody secrets.
Boston Scientific earnings hit by cyberattack fallout
Medical device giant warns August intrusion will dent Q3 and full-year sales and earnings as recovery drags on.
Spending Spree Unravels $240M Crypto Heist
Young scammers' lavish purchases led FBI to suspects in $240M bitcoin theft.